Impact
Unauthenticated broken access control in the WordPress WPMobile.App plugin allows any external user to reach functions and settings that are intended to be restricted to authenticated users, mapping to CWE‑862. The flaw could enable an attacker to view or manipulate protected data, potentially compromising confidentiality or integrity, and may also serve as a foothold for further privilege escalation or exploitation of other components on the site.
Affected Systems
The vulnerability is present in WordPress sites that run the WPMobile.App plugin version 11.77 or earlier, all issued by Amauri. Dependent releases after 11.78 have the fix applied; no other affected version ranges are listed.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity risk, while the EPSS score is not available, leaving the exploitation probability uncertain. The vulnerability is not listed in the CISA KEV catalog. Because it permits unauthenticated access to restricted endpoints, an attacker would need only a crafted request sent from the public internet, a low‑effort attack path with no special credentials required.
OpenCVE Enrichment